Overview
The Cybersecurity Maturity Model Certification (CMMC) Assessment Guide provides detailed criteria and methodologies used by assessors to evaluate whether defense contractors meet required cybersecurity controls for protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It supports a tiered assessment model aligned with three maturity levels, defining specific practices, objectives, and evidence needed to demonstrate compliance with standards such as NIST SP 800-171. The guide ensures consistency and rigor in assessments by outlining how controls are verified, including documentation review, interviews, and testing procedures. It is used to validate that organizations have effectively implemented required safeguards as a condition for participating in U.S. Department of Defense contracts.